Skip to content

EntraID OAuth support. #846

Description

@thechiefn

I saw this closed issue #26 and the documentation notes here: https://tinyauth.app/docs/reference/authentication. I've been using AzureAD / EntraID for a while now with the following configuration:

EntraID configuration parameters

TINYAUTH_OAUTH_PROVIDERS_GENERIC_CLIENTID=< CLIENTID >
TINYAUTH_OAUTH_PROVIDERS_GENERIC_CLIENTSECRET=< CLIENTSECRET >
TINYAUTH_OAUTH_PROVIDERS_GENERIC_AUTHURL=https://login.microsoftonline.com/< TenantID >/oauth2/v2.0/authorize
TINYAUTH_OAUTH_PROVIDERS_GENERIC_TOKENURL=https://login.microsoftonline.com/< TenantID >/oauth2/v2.0/token
TINYAUTH_OAUTH_PROVIDERS_GENERIC_USERINFOURL=https://graph.microsoft.com/oidc/userinfo
TINYAUTH_OAUTH_PROVIDERS_GENERIC_SCOPES=openid,email,profile
TINYAUTH_OAUTH_PROVIDERS_GENERIC_REDIRECTURL=https://< tinyauth >/api/oauth/callback/generic
TINYAUTH_OAUTH_PROVIDERS_GENERIC_NAME=< your display name >
TINYAUTH_OAUTH_PROVIDERS_GENERIC_INSECURE=false
TINYAUTH_UI_TITLE=< UI NAME >

Here's the metadata for the endpoints too:
https://login.microsoftonline.com//v2.0/.well-known/openid-configuration

Image

offline_access isn't needed in this case, but the automation I have in place to build service principles / app registrations adds it automatically.

This is a standard configuration for EntraID Oauth2 support. Honestly, I don't even think i've seen the debug logs on TinyAuth so I could be way off here, and I apologize for opening up an issue to bring it up if that's the case. I'm happy to help document this out to have it included, or get a EntraID tenant set up for TinyAuth testing.

Activity

  1. scottmckendry commented on May 22, 2026

    @scottmckendry
    Member

    I think it's important to point out that Entra doesn't guarantee an email claim to be returned, even if the permission is granted in the app registration.

    Based on my limited understanding, it's likely the user configured in the original linked issue didn't have a mail address. Entra ID treats mail as a separate field to UPN, and they're often confused.

    From MS docs:

    ...the Microsoft identity platform produces the name claims, subject claim, and email when available and consented to.

    The key point here is "when available". Just to double check, does your user have the mail filed populated? Are you able to set up a test user without a mail address to see if we can reproduce the behaviour?

  2. thechiefn commented on Aug 24, 2026

    @thechiefn
    Author

    for Work / School accounts, it's true that you don't have to be licensed and you won't receive an email attribute on your user object. There is plenty of documentation online to pass the UPN parameter through to the email token during the auth flow. This is the common failure mode for accounts that don't have email address. UPN is required
    https://community.auth0.com/t/entra-ad-users-without-email-cannot-accept-organization-invite/199740/5

    There's a few other places this is documented online. I would be happy to write the steps and have it included with TinyAuth as an option. I hate seeing EntraID is not supported because it will easily turn people off from using TinyAuth.

  3. steveiliop56 commented on Aug 24, 2026

    @steveiliop56
    Member

    Quick update on this. With #1087 you will be able to do claim mapping. This means that you can use irregular claims from the user-info endpoint. For example, if Entra returns foo_email in user-info, you can use the following configuration option:

    TINYAUTH_OAUTH_PROVIDERS_ENTRAID_CLAIMS_EMAIL=foo_email

    and Tinyauth will get the email from the foo_email claim. I haven't tested this with Entra and this is as far as I am willing to go with supporting it. This option (and the rest for groups, username and name) is not just for Entra but for any OpenID Connect provider that mostly implements the specification.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

enhancementNew feature or request

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions